2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-57774MEDIUM4.8A cross-site scripting (XSS) vulnerability in the getBusinessUploadListPage?busid interface of JFinalOA before v2025.01....
CVE-2024-57773MEDIUM4.8A cross-site scripting (XSS) vulnerability in the openSelectManyUserPage?orgid interface of JFinalOA before v2025.01.01 ...
CVE-2024-57772MEDIUM4.8A cross-site scripting (XSS) vulnerability in the /bumph/getDraftListPage?type interface of JFinalOA before v2025.01.01 ...
CVE-2024-57771MEDIUM4.8A cross-site scripting (XSS) vulnerability in the common/getEditPage?view interface of JFinalOA before v2025.01.01 allow...
CVE-2024-57770HIGH8.8JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component apply/save#oaContr...
CVE-2024-57769HIGH8.8JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component borrowmoney/listDa...
CVE-2024-57768CRITICAL9.8JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component validRoleKey?sysRo...
CVE-2024-50633HIGH7.5A Broken Object Level Authorization (BOLA) vulnerability in Indico through 3.3.5 allows attackers to read information by...
CVE-2024-41746MEDIUM6.1IBM CICS TX Advanced 10.1, 11.1, and Standard 11.1 is vulnerable to stored cross-site scripting. This vulnerability allo...
CVE-2024-37181LOW2.6Time-of-check time-of-use race condition in some Intel(R) Neural Compressor software before version v3.0 may allow an au...
CVE-2024-57611LOW3.507FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/doAdminAction.php?act=editShop&s...
CVE-2024-57162HIGH7.2Campcodes Cybercafe Management System v1.0 is vulnerable to SQL Injection in /ccms/view-user-detail.php.
CVE-2024-57161MEDIUM4.307FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaWorkReport/edit...
CVE-2024-57160MEDIUM4.307FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaTask/edit.html.
CVE-2024-57159LOW3.507FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaWorkReport/add....
CVE-2024-50563CRITICAL9.8A weak authentication in Fortinet FortiManager Cloud, FortiAnalyzer versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, F...
CVE-2024-13387MEDIUM6.4The WP Responsive Tabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wprtabs' shor...
CVE-2024-13355MEDIUM5.4The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to limited fi...
CVE-2024-12615MEDIUM6.5The Passwords Manager plugin for WordPress is vulnerable to SQL Injection via the $wpdb->prefix value in several AJAX ac...
CVE-2024-12614MEDIUM4.3The Passwords Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit...
CVE-2024-12613HIGH7.5The Passwords Manager plugin for WordPress is vulnerable to SQL Injection via the $wpdb->prefix value in several AJAX fu...
CVE-2024-12427MEDIUM5.3The Multi Step Form plugin for WordPress is vulnerable to unauthorized limited file upload due to a missing capability c...
CVE-2024-48885CRITICAL9.1A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiRecorder...
CVE-2024-45331HIGH7.8A incorrect privilege assignment vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.3, FortiAnalyzer 7.2.0 throug...
CVE-2024-12226MEDIUM6.5In affected versions of the Octopus Kubernetes worker or agent, sensitive variables could be written to the Kubernetes s...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now